Skip to content

Releases: GSA/smartpay-training

SmartPay Training Sprint 55 Release v8.1

19 May 12:44
e41018c

Choose a tag to compare

This sprint release contains the following:

  • Code Scanning Alert: Workflow Does Not Contain Permissions
    #815
  • Code Scanning Alert: Workflow Does Not Contain Permissions
    #818
  • Code Scanning Alert: Workflow Does Not Contain Permissions
    #817
  • Code Scanning Alert: Workflow Does not Contain Permissions
    #820
  • Code Scanning Alert: Workflow Does Not Contain Permissions
    #816
  • Code Scanning Alert: Workflow Does not Contain Permissions
    #819

SmartPay Training Sprint 54 Release v8.0

05 May 15:25
d3eef1a

Choose a tag to compare

This sprint contains the following:

  • Integration to Application Security as a Service (AppSECaaS)
    #654
  • Dependabot Alert: esbuild enables any website to send any requests to the development server and read the response
    #762
  • Upgrade to Astro 5.0
    #795
  • Dependabot Alert: PrismJS DOM Clobbering vulnerability
    #783
  • Dependabot Alert: Babel has inefficient RexExp complexity in generated code with .replace when transpiling named capturing groups
    #789
  • Dependabot Alert: Vite bypasses server.fs.deny when using ?raw??
    #801
  • Dependabot Alert: Vite has an server.fs.deny bypass with an invalid request-target
    #808
  • Dependabot Alert: Vite has a server.fs.deny bypassed for inline and raw with ?import query
    #800
  • Dependabot Alert: Vite allows server.fs.deny to be bypassed with .svg or relative paths #83
    #799

SmartPay Training Sprint 53 Release v7.2

18 Apr 14:26
ce1571c

Choose a tag to compare

This sprint release contains the following:

  • Add Admin Role to User - Varuna Singh
    #809
  • Dependabot Alert: tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
    #803
  • Dependabot Alert: Axios Requests Vulnerable to Possible SSRF and Credential Leakage via Absolute URL
    #802
  • UI: Add link to Program Website, Contacts, and FAQ on Training Application
    #696
  • Dependabot Alert: Gunicorn HTTP Request/Response Smuggling vulnerability
    #788

SmartPay Training Sprint 52 Release v7.1

07 Apr 14:10
fc12b9a

Choose a tag to compare

This sprint release contains the following:

  • Audit Logging on Training Reports
    #772
  • April 2025 Separation Report
    #792
  • New Admin Report: Users with Roles Assigned
    #758
  • Dependabot Alert: Axios Requests Vulnerable to Possible SSRF and Credential Leakage via Absolute URL
    #782

SmartPay Training Sprint 51 Release v7.0

25 Mar 13:24
4332bf0

Choose a tag to compare

This sprint release contains the following:

  • GSPC Report Enhancements
    #644
  • Bug: Alphabetize Credit Cards on P/C Travel Training Lesson 1
    #776
  • GSPC - Ability to Send Additional Notifications to Invited Users
    #655
  • GSPC- Add Unique GUID to each email sent
    #678
  • GSPC Email Functionality
    #640
  • Static Code Vulnerability: Vulnerability Contained in USWDS Library
    #697
  • Bug: GSPC Verify your GSA SmartPay Program Certification (GSPC) Coursework and Experience Email Errors
    #754
  • Bug: Alphabetize Credit Cards when listed on various screens
    #771

SmartPay Training Sprint 50 Release v6.10

07 Mar 17:47
fba21bf

Choose a tag to compare

This sprint release contains the following:

  • Update the signature on all certificates
    #755

SmartPay Training Sprint 49 Release v6.9

24 Feb 14:50
2a6890a

Choose a tag to compare

This sprint release contains the following:

  • User Certification - Export of Users with the Reporting Role & Admin Role
    #757
  • Dependabot Alert: Websites were able to send any requests to the development server and read the response in vite
    #753
  • Dependabot Alert: Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
    #750

SmartPay Training Sprint 48 Release v6.8

10 Feb 14:00
42a7ced

Choose a tag to compare

This sprint release contains the following:

  • Federal Website Standards - Meta Page Descriptions
    #715
  • Remove All Content/References to Executive Order (E.O.) 14081
    #746
  • Add Asterisk to the 4-digit Prefixes where referenced throughout website and add additional content
    #745
  • Federal Website Standards - HTML Page Titles
    #714

SmartPay Training Sprint 47 Release v6.7

24 Jan 15:34
6f089f3

Choose a tag to compare

This sprint release contains the following:

  • Dependabot Alert: Atro CSRF Middleware Bypass (security.checkOrigin)
    #720
  • Dependabot Alert: Astro's server source code is exposed to the public if source maps are enabled
    #725
  • Update to the latest version of USWDS 3.11.0
    #722
  • BUG: Training Report - Selecting an Agency w/o Bureau No Results Returned
    #728
  • Update SMTP to reflect GSA IT naming convention standard
    #736

SmartPay Training Sprint 46 Release v6.6

14 Jan 16:53
9ca102e

Choose a tag to compare

This sprint release contains the following:

  • BUG: Admin/User Profile Saved Changes are Not Displayed on Results screen
    #709
  • BUG: Insert a space between the date field of Completion date range end and Quiz type(s) on the SmartPay Training Report
    #705
  • Customizable Training Report for A/OPC
    #633